Technical audit · 2026-06-15

esploradati.istat.it

National Institute of Statistics of Italy, Data Portal

ISTAT's statistical-data portal. 82 requests, only 2 domains. The policy is one of the most precise in the series: it names the analytics tools individually and describes the IP masking down to the byte, and the capture confirms this. Cookies are not set, the fonts are self-hosted, there is no profiling. The only catch is that one JS library is loaded from a third-party CDN not named in the policy.

Timeline of the leak

+0–231 ms · application load
The data portal's React application. The Dynatrace monitoring agent loads from its own domain at +158 ms. All the main code and fonts are self-hosted.
not applicable — there is no banner, and it is not needed
There is no consent banner, and this is lawful. Only technical cookies and pseudonymised analytics on its own infrastructure, without profiling, are used. There is nothing to ask consent for.
+1487–43574 ms · CDN and telemetry
At +1487 and +1602 ms — the only outward request throughout the entire session: the less@2.7.2 library from cdn.jsdelivr.net. The Dynatrace telemetry goes out later, as the data is worked with (+10224…+43574 ms), which matches the declared pseudonymised analytics.

Declared versus actual

Matomo (IP masked by 2 bytes) — заявлен
Dynatrace (IP masked by 1 byte) — заявлен
+ cdn.jsdelivr.net (less@2.7.2 library) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

esploradati.istat.it is the portal for interactive access to the statistical data of Italy’s National Institute of Statistics (ISTAT). It is a React application for viewing datasets with a mapping module. The capture shows 82 requests to only two domains: the portal itself and one external CDN. The policy correctly names ISTAT itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is another of those rare cases where comparing the document with the fact gives an almost complete match. So, as in similar clean cases, the analysis is mainly about what is done right — and about one small catch.

There is no banner, and this is lawful. On the site there are only technical cookies and pseudonymised analytics on its own infrastructure, without profiling cookies. There is nothing to ask consent for, so no banner is needed. Its absence here is natural, not an oversight.

The policy is precise down to the byte

Here credit is due directly and in detail, because such a thing is not often encountered. The policy names both analytics tools — Matomo and Dynatrace — and describes their privacy configuration down to the byte: in one, the last two bytes of the IP address are zeroed on masking, in the other, the last one. It states that no profiling is conducted, that the data is pseudonymised, and that navigation data is stored no longer than ninety days. This is one of the most specific and honest documents in the whole series — it does not get by with general words, but describes exactly what is technically configured.

What the capture showed

The picture corresponds. The whole site runs on its own domain, the fonts are self-hosted (not loaded from Google, unlike a number of other government sites). Not a single cookie was set throughout the entire session. Of the declared pair of tools, one actually fired in this capture — Dynatrace: its agent loaded immediately, and the telemetry went out later, as the user worked with the data. This is consistent with the description — first-party monitoring with a masked IP. Here is an honest correction: Matomo, although declared in the policy, did not fire in this particular capture — no requests to it were recorded. This does not mean it is absent altogether: it may not have launched on this page of the application or in this scenario. But to claim that «both tools fired» cannot be done from this capture — only Dynatrace fired.

The only catch — an external CDN

And here is the only discrepancy with the document. One JS library — the CSS preprocessor less — is loaded not from its own server, but from a third-party CDN. This is two requests throughout the whole session, and it is not a tracker in the behavioural sense: the library tracks nothing. But formally, when it loads, the visitor’s IP address goes to a third-party service that is not named in the policy by a single word. The catch is minimal, and eliminated trivially — exactly as ISTAT has already handled the fonts: it is enough to place the library on its own server, and the last outward request disappears.

What cannot be claimed from the capture

A few honest caveats. As stated, the absence of Matomo in this capture does not prove it does not work in other scenarios — I record only that in this session it was not called. The content of the Dynatrace telemetry goes out in the request body, which is not preserved in the lightweight export, so on the IP masking I rely on the policy text — and it is consistent with there being no cookie and no persistent identifier. The capture covers one page of the application; the exact server IP addresses are absent from the export.

Conclusion

This is one of the cleanest sites in the series, on a par with the best. The policy is specific down to the byte and matches reality, the analytics is first-party and pseudonymised, there is no profiling, cookies are not set, the fonts are self-hosted, the controller is named correctly, there are no false promises about non-transfer abroad. The only thing that stands out is one utility library pulled from a third-party CDN not named in the document. Against the backdrop of sites that leaked visitors to Google and Meta, this is the difference between an almost impeccable execution and a single minor shortcoming. The main takeaway for the reader: this is what a site that handles a visitor’s data honestly looks like — and one unclosed trifle here only underscores the general order.

Evidence
Original (audit)
HAR file: it/esploradati-istat-it-2026-06-15.har
SHA-256: b4e5c42155afa13669833d23e3db40564ac68cb295ecadae4d0473522c4f4bc1
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website esploradati.istat.it.

2. Circumstances
I visited the website esploradati.istat.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The service cdn.jsdelivr.net is not mentioned in the policy either as a data recipient or as a component used. When the less@2.7.2 library (a CSS preprocessor) loads, the visitor's IP address is transmitted to this third-party CDN. This is not a behavioural tracker but an infrastructure dependency, yet formally a data recipient that is not in the document. It is fixed the same way ISTAT has already handled the fonts — by moving the library to its own server.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-esploradati-istat-it/

3. Provisions violated
Art. 13(1)(e) GDPR — the third-party CDN is not named

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]